Windows Events Log could use improvement in usability. I will describe how the product we use today does it which works great. That same product is very poor at all the other stuff you do well so i would prefer for you guys to get windows event logging up to their level.
Create Event Set Templates
-These are a grouping of event filters. Such as SQL Server Event Set, Exchange Event Set, HP Hardware Monitoring Event Set,
...more »
Windows Events Log could use improvement in usability. I will describe how the product we use today does it which works great. That same product is very poor at all the other stuff you do well so i would prefer for you guys to get windows event logging up to their level.
Create Event Set Templates
-These are a grouping of event filters. Such as SQL Server Event Set, Exchange Event Set, HP Hardware Monitoring Event Set, Dell hardware Monitoring Event Set, Active Directory Event Set, DNS Event Set, DHCP Event Set, etc. Typically each role a server can have means a new event set template. The event filters are typically specify the source with * next to category and event id. Then there are ignores for specific events that are useless within that source. Any given event set template will have 5-20 specific ignores to weed out the false possitive. Then we we get a new server online we match up the roles with the event set templates. We also have a global ignore event set that applies to every server type. If we get false possitives or alerts for a given server we have a couple of options
1.) Assign it to the global ignore event set template if no server should ever have this triggered.
2.) Create a customer specific deviation from the event set template that triggered. So if it was an exchange event set i would copy the exchange event set and call it server X exchange event set and add a new ignore.
This type of system allows you to start with a quick and dirty template based on role and then fine tune for the specific server.
The other challenge we have with the current system and maybe you can help out is event log types. If you don't assign the appropriate event set to the appropriate event log(application, Security, System) then you don't get the alert.
« less
full details »
Social Web